Google DeepMind has extended its watermarking technology from images and audio into biology. The company published SynthID Bio in Nature on 30 September, in a paper on function-preserving watermarking of AI-generated proteins, describing a method that embeds verifiable signatures into protein sequences designed by AI models and into the 3D structures those models predict, and said lab tests showed the watermarked designs worked as well as unmarked ones.
The signature goes into the model itself rather than being added afterwards. DeepMind built the watermark into the weights of ProteinMPNN, a widely used protein design model, and fine-tuned the diffusion network inside AlphaFold 3 so that predicted structures carry a mark in their atomic coordinates. That second part means a signature can be checked against a protein that has actually been made and analysed in a lab, not just against a digital file.
DeepMind has released the code, the model weights and its laboratory data, and says the detection methods are available to the research community.
The Lab Results
The main question for any watermark in biology is whether the mark damages the product. DeepMind tested watermarked ProteinMPNN alongside AlphaProteo, its protein binder design system, against three targets: VEGF-A, a growth factor involved in cancer and eye disease; the receptor-binding domain of the SARS-CoV-2 spike protein; and PD-L1, a protein central to cancer immunotherapy.
On all three, the watermarked designs matched the unwatermarked ones on hit rate, which measures how many designs actually bind their target, on binding strength, and on the diversity of the sequences produced. Detection of the watermark in predicted structures was close to perfect, and the signal survived digital noise and small changes to coordinates.
Work with Brian Hie's lab at Stanford and the Arc Institute went further, putting SynthID Bio into Evo 2, a model that designs genomes rather than single proteins. Watermarked bacteriophages, viruses that infect bacteria, remained functional in bacterial cultures, with a technical paper still to come.
Why DNA Synthesis Companies Care
The reason DeepMind built this sits in the supply chain for synthetic biology. Companies that make DNA to order screen incoming sequences against databases of known dangerous agents before they synthesise anything, a system that works well when a sequence resembles something already catalogued.
AI-designed proteins break that assumption, because a model can produce a sequence that performs a given function while looking nothing like any natural protein in the reference databases. A watermark offers a different signal, one of provenance rather than similarity: it tells the synthesis provider that an order came from a model with known safeguards, which lets staff focus attention on orders that carry no such mark.
"A promising new addition to the biosecurity toolbox that could strengthen screening," said James Diggans, vice president of policy and biosecurity at Twist Bioscience, one of the largest DNA synthesis companies.
Other Uses Beyond Screening
The same signature helps elsewhere. Curators of scientific databases could spot AI-designed sequences submitted without that label, and journals and research institutions could check the provenance of designs in submitted work.
That kind of provenance checking has become routine for AI-generated media. DeepMind says SynthID has now marked more than 100 billion images and videos and over 60,000 years of audio, and the technology is used by OpenAI, Nvidia and Kakao.
What A Watermark Cannot Do
DeepMind is direct about the limits. The company says watermarking is not a silver bullet, and names resistance to deliberate tampering as the main unsolved problem: someone determined to strip or alter a signature has options, particularly with an open-source model whose weights they control.
It recommends pairing watermarks with other measures, including metadata that records where a design came from, central repositories of designed sequences, safeguards built into the models themselves, and vetting of customers by synthesis providers. A watermark identifies designs from cooperating models, so its value depends on how many developers adopt it, which is part of why DeepMind has released the code openly.
An Honest Signal, Not A Filter
The distinction matters for how the tool gets used. A watermark cannot tell a screening system whether a sequence is dangerous; it tells the system where the sequence came from. That turns screening into a question about trusted sources rather than a search for resemblance to known threats, and it only works if the trusted sources cover a large share of real design work.
Provenance Becomes The Pattern
SynthID Bio reflects a wider shift in how AI companies handle risk. Rather than trying to detect harmful output after the fact, developers are increasingly building signals of origin into what their models produce, so that downstream systems, whether a DNA synthesis provider or a content platform, can act on where something came from.
The same logic is spreading through industrial systems, where sensors and machines increasingly need to prove what they are and where their data originated before anything acts on it, a shift we traced in how physical AI turns IoT sensing into action. In both cases, trust rests on provenance that travels with the thing itself.
"Empower developers to lead on safety," said biosecurity policy expert Sarah Carter of the approach, while Pushmeet Kohli, who leads science and strategic initiatives at Google DeepMind, said progress should be measured by the foresight and responsibility guiding new capabilities.
What To Watch Next
Adoption will decide how much this matters. DeepMind has made the technology available, but it will only shape screening if other protein design model developers build in compatible watermarks and if synthesis providers wire detection into their order checks.
Standards bodies and regulators will also have a say, since governments have been updating guidance on screening synthetic nucleic acid orders, and a provenance signal that works across models would be easier to write into policy than one tied to a single company's tools.
Biology Gets Its Own Provenance Layer
SynthID Bio shows that a watermark can ride along inside a designed protein without weakening it, which was the open technical question. That makes provenance a practical option for AI-designed biology rather than a theory, and it gives synthesis providers something to check beyond similarity to known threats.
The harder problems are organisational. A watermark that only some developers use, and that a determined actor can remove, works as one layer among several rather than a barrier on its own. Whether this becomes a real safeguard depends less on DeepMind's laboratory results than on how many other labs and companies decide to mark their work the same way.